GitLab has released patches for a critical vulnerability in its AI Gateway, identified as CVE-2026-90970, which could enable an authenticated user to execute arbitrary commands on self-hosted gateway instances. The flaw, which carries a CVSS score of 9.9, was publicly disclosed by GitLab on October 2, 2026.
The vulnerability specifically affects the handling of custom flow prompt templates within the AI Gateway. According to GitLab, an authenticated user with access to the Duo Agent Platform could craft a special flow configuration to escape the prompt template sandbox. This escape would then allow for arbitrary command execution on the AI Gateway host. It is important to note that the attack requires prior authentication and access to the Duo Agent Platform; it is not an unauthenticated vulnerability.
GitLab has confirmed that the security fix has been deployed to its own cloud-based AI Gateways. Consequently, customers utilizing GitLab.com, GitLab Dedicated, or self-managed GitLab instances connected to a GitLab-hosted gateway do not need to take any action. The update is critical for organizations running a self-hosted GitLab AI Gateway, which is typically done to maintain AI requests and responses within their own infrastructure. GitLab has directly contacted these customers and strongly advises immediate updates.
The affected AI Gateway versions include 18.1.6 through 19.2.3, which should be updated to 19.2.4; versions 19.3.0 through 19.3.1, which require an update to 19.3.2; and version 19.4.0, which needs to be updated to 19.4.1.
The AI Gateway serves as an intermediary layer between GitLab Duo features (such as code suggestions, chat, and agentic workflows) and the underlying AI models. In self-hosted deployments, it processes requests between the GitLab instance and the organization's AI infrastructure. This service also handles sensitive authentication material, including JSON Web Token signing and validation keys, which are passed to the gateway as environment variables. Therefore, successful command execution on the gateway could provide an attacker with a foothold in infrastructure responsible for AI requests and authentication. The precise impact would depend on the specific deployment configuration and the gateway's access within the organization's environment.
GitLab credited the HackerOne researcher "invisiblemeerkat" for responsibly reporting the vulnerability. As of the October 2 advisory, GitLab has not indicated that CVE-2026-90970 has been exploited in the wild, nor has it released a public proof of concept or detailed technical exploitation steps. This leaves some specifics regarding the exact flow configuration needed for exploitation and the precise conditions for command execution unaddressed.






